--- layout: default title: "Open Letter to Members of the European Parliament of the Civil Liberties, Justice and Home Affairs Committee" description: "An October 2013 CIS open letter by Elonnai Hickok expressing support for the EU's proposed General Data Protection Regulation, while raising four concerns around purpose limitation, interpretation of broad terms, jurisdictional scope, and foreign intelligence access, sent as part of a joint initiative with Privacy International and other NGOs." authors: ["Elonnai Hickok"] categories: [Centre for Internet and Society, Elonnai Hickok] date: 2013-10-23 source: "Centre for Internet and Society" permalink: /elonnai/open-letter-members-european-parliament-civil-liberties-justice-home-affairs-committee/ created: 2026-08-25 homepage_featured: true --- **"Open Letter to Members of the European Parliament of the Civil Liberties, Justice and Home Affairs Committee"** is an open letter by [Elonnai Hickok](/elonnai/) published by the [Centre for Internet and Society](/cis/) on 23 October 2013. Written on behalf of CIS, Bangalore, it expresses support for the European Commission's proposed General Data Protection Regulation while raising four specific concerns, and was sent as part of a joint initiative coordinated by Privacy International and a number of other NGOs. ## Contents 1. [Article Details](#article-details) 2. [Full Text](#full-text) 3. [Context and Background](#context-and-background) 4. [External Link](#external-link) ## Article Details
📰 Published by:
Centre for Internet and Society
📅 Date:
23 October 2013
✍️ Author:
Elonnai Hickok
📄 Type:
Open letter
🔗 Original Link:
Read the original post
## Full Text

An open letter was sent to the Members of the European Parliament of the Civil Liberties, Justice and Home Affairs Committee on the proposed EU Regulation. The letter was apart of an initiative that Privacy International and a number of other NGO's are undertaking.


Dear Members of the European Parliament of the Civil Liberties, Justice and Home Affairs Committee,

On behalf of The Centre for Internet and Society, Bangalore, India, we are writing to express our support of the European Commission's proposed General Data Protection Regulation (COM (2012) 11).

The legal framework established under the 1995 Data Protection Directive (95/46/EC) in Europe has positively influenced many existing privacy regimes worldwide, serving as a model legal framework in jurisdictions that are in the process of developing privacy regimes, including India. The positive impact of the Data Protection Directive shows the potential of the Regulation to become a global model for the protection of personal data. The Regulation seeks to address new scenarios that have arisen in the context of rapidly changing technologies and practices, increasing its potential for positively influencing privacy rights for individuals globally.

India is currently in the process of considering the enactment of privacy legislation, in part with the aim of ensuring adequate safeguards to enable and enhance information flows into India from countries around the world, including Europe. At the same time, India is seeking Data Secure Status from the EU, on the basis of its current regime.

It is clear that the EU framework for data protection has a major influence on the current and emerging privacy regime in India. India is only one country of many that are in the beginning stages of developing a comprehensive privacy regime. Thus, we ask that you keep in mind how the Regulation will impact the rights of individual in countries outside of Europe, particularly in countries that are in the process of developing privacy regimes.

We ask that you take into consideration the four following points that we believe need to be addressed in the Regulation to help ensure adequate protection of the rights of individuals in the European Union and around the world.

  1. Strengthen the principle of purpose limitation: The Regulation should incorporate a strong purpose limitation principle that strictly limits present and future uses of personal data to the purposes for which it was originally collected. Currently, Article 6(4) allows for the further processing of data when the processing is "not compatible with the one for which the personal data have been collected". Though the provision establishes legal requirements, one of which must be before information can be used for a further purpose, this is has proven insufficient in the existing Directive. The current provision in the Regulation dilutes the principle of purpose limitation as well as weakening an individual's ability to make informed decisions about their personal data.
  2. Define principles for interpretation of broad terms: The Regulation should create principles for interpreting broad terms such as "legitimate interest" and "public interest". These vague terms are used throughout the Regulation, and create the potential for loopholes or abuse. Because these terms can be interpreted in many different ways, it is important to create a set of principles to guide their interpretation by data protection authorities and courts to avoid inconsistent application and enforcement of the Regulation.
  3. Clarify the scope of the Regulation: The Regulation should clearly describe the jurisdictional scope and reach of its provisions. Currently Article 3(1) states that the Regulation will apply to the processing of data "in the context of the activities of an establishment of a controller or a processor in the Union". The flow of information on the online environment coupled with trends such as cloud computing, outsourcing, and cross border business creates a scenario where defining what constitutes "context of the activities of an establishment", is difficult and could lead to situations where personal data is not protected, as the collection, use, or storage of it does not necessarily fall within the "context of the activities".
  4. Address access by foreign alliance bodies: In light of growing demands by law enforcement for access, use, and transfer of personal information for investigative purposes across jurisdictions – the Regulation should define the circumstances in which personal data protected by its provisions can be accessed and used by foreign intelligence bodies, and the procedure by which to do so. The Regulation should address challenges such as access by foreign intelligence bodies to data stored on the cloud and data that has passed through/is stored on foreign networks/servers.
{% include back-to-top.html %} ## Context and Background In October 2013, the Centre for Internet and Society (CIS) published an open letter by Elonnai Hickok addressed to Members of the European Parliament sitting on the Civil Liberties, Justice and Home Affairs Committee, expressing support for the European Commission's proposed General Data Protection Regulation, formally identified as COM (2012) 11. The letter was submitted as part of an initiative involving Privacy International and a number of other non-governmental organisations. Writing on behalf of CIS's Bangalore office, Hickok grounded the letter's argument in the influence of the EU's earlier 1995 Data Protection Directive (95/46/EC), which she described as having served as a model legal framework for jurisdictions developing their privacy regimes, including India. The letter argued that the new Regulation could have similar influence, particularly given its attempt to address newer challenges arising from rapidly changing technologies and practices. The letter situated this argument within India's own contemporaneous policy position: India was, at the time, both considering its own privacy legislation, partly to facilitate stronger cross-border data flows with Europe, and simultaneously seeking "Data Secure Status" from the EU based on its existing regulatory framework, a request CIS had separately and publicly opposed in its own June 2013 open letter to European Data Protection Commissioners. Given this context, Hickok urged the Committee to consider how the Regulation would affect individuals in countries outside Europe that were still in the early stages of building comprehensive privacy protections. The letter raised four specific drafting concerns. First, it argued that Article 6(4)'s "compatible use" standard for further processing of personal data was too weak a formulation of the purpose limitation principle, and risked undermining individuals' ability to make informed decisions about their own data. Second, it called for interpretive principles to govern vague terms such as "legitimate interest" and "public interest" used throughout the Regulation, to prevent inconsistent enforcement across member states. Third, it flagged that Article 3(1)'s jurisdictional trigger, tied to data processing "in the context of the activities of an establishment... in the Union," could create difficulties in situations involving cloud computing, outsourcing, and cross-border business operations, potentially leaving some personal data outside the Regulation's protection. Fourth, and reflecting a concern that ran through several of CIS's contemporaneous surveillance-related posts, the letter urged the Regulation to explicitly define when and how foreign intelligence agencies could lawfully access personal data protected under EU law, including data held on cloud infrastructure or routed through foreign networks and servers. ## External Link - [Open Letter to Members of the European Parliament of the Civil Liberties, Justice and Home Affairs Committee](https://cis-india.org/internet-governance/blog/open-letter-members-european-parliament-civil-liberties-justice-home-affairs-committee) on CIS website {% include navbox-elonnai.html %}